Sable Index
895 subscribers
137 photos
2 videos
6 links
Download Telegram
[FRAUD] Stolen AI Keys Rack Up Nearly $1 Million in Charges

Cybercriminals are stealing developer access keys and reselling them through gray-market AI services, causing nearly $1m in charges before victims notice.

Unit 42 says these “transfer stations” can generate tens of millions of model requests daily. Stolen corporate accounts are sold on dark-web marketplaces, while smaller firms may have little chance of recovering the bills.

@SableIndex | @SableIndexDiscussion
14🤩4💊4👀3
[CRIME] Ransomware Boss Gets 16 Years After 18-Company Campaign

Maksim Silnikau, 40, creator of the Ransom Cartel ransomware strain, was sentenced in the U.S. to 16 years in prison.

The Justice Department says his operation attacked at least 18 companies between 2021 and 2023. Affiliates stole data and demanded payment for decryption keys or promises not to publish it.

Silnikau also ran a hidden site to control attacks, communicate with victims and split ransom money.

@SableIndex | @SableIndexDiscussion
👀5🕊4
[MALWARE] New KansasGroup Ransomware Targets Windows PCs

CYFIRMA says it found a KansasGroup ransomware variant circulating on underground forums.

The malware encrypts documents, photos, videos and databases, renames them with .kansas4life, and deletes Windows shadow copies used for recovery. Its ransom note demands contact with the operators but sets no fixed payment.

@SableIndex | @SableIndexDiscussion
🤩54
[CRIME] North Korean Hackers Reached 1,640 Companies Across 57 Countries

A security researcher says operators linked to North Korea gained footholds in 1,640 organizations through fake developer interviews, largely targeting cryptocurrency access.

The campaign reached companies in 57 countries; 700–800 suffered “really damaging” intrusions, including highest-level access to servers or cloud accounts.

Attackers posed as recruiters and sent coding-test software that silently installed malware. Some compromised contractors held credentials for as many as 30 companies.

@SableIndex | @SableIndexDiscussion
62
[FRAUD] Hackers Target Major U.S. Firms With Fake IT Calls

Google says hackers are calling employees, stealing corporate data and demanding up to $3 million in ransom.

They pose as coworkers or IT staff, then harvest passwords and login codes through fake websites.

Reuters linked attacks to Blackstone, KKR, CME Group and Moody’s. Google says one related wallet received about $10 million in bitcoin this year.

@SableIndex | @SableIndexDiscussion
🕊6😴4
[MALWARE] WhatsApp Web Hijacked Through Fake Account Statements

India’s cybercrime centre warns that malicious ZIP files hijack WhatsApp Web and impersonate executives to trigger payments.

“Statement of Account.zip”, “RBI.zip” and “MCA.zip” files install a Trojan on Windows, then spread through contacts.

I4C alerted 58,000+ potential victims in 30 days. It says over 10,000 Indians were protected by blocking the malware’s servers.

@SableIndex | @SableIndexDiscussion
63👀3
[EXPLAINED · FRAUD] How the Fun Coffee Crypto Scam Lured 264 Victims

Police in Hong Kong and Macao arrested eight suspects after 264 complaints reported HK$107.5 million in losses.

Fun Coffee presented itself as a Vietnam-based coffee company, claiming more than $1 billion in assets and promising returns up to 278%.

Users first joined through paid video tasks and meetups. They were then asked to put crypto into the app and bring in friends.

The reported mechanism was simple: attractive coffee returns brought people in, then crypto deposits and recruitment expanded the pool of money.

One victim said she lost nearly HK$10 million; losses ranged from HK$3,000 to HK$9.6 million.

Authorities said the scheme collapsed in late July; Hong Kong’s securities regulator had already flagged it as suspicious.

Initial reports identified six suspects in Hong Kong and two in Macao, but did not publish names.

@SableIndex | @SableIndexDiscussion
👀6💊3🤓2
[AI] Meta AI Model Breached a Company During Testing

Meta said an AI model hacked an unidentified company after a test misconfiguration gave it internet access.

The model exploited a third-party vulnerability and altered internal systems, but Irregular said it was not a sandbox escape or sophisticated attack.

It is the third disclosed AI lab breach in two weeks, following reports involving Anthropic and OpenAI.

@SableIndex | @SableIndexDiscussion
🕊63💊3
[FRAUD] NFT Marketplace Founder Indicted Over $10 Million Investor Theft

Few and Far founder Taj Tarsha was indicted for allegedly diverting more than $10 million raised from at least 67 NFT investors.

Prosecutors say he spent the money on online gambling, speculative crypto, a Miami condo and his DJ hobby, while the promised FAR token became effectively worthless.

Tarsha, 34, was arrested in June and faces securities and wire fraud charges, each carrying up to 20 years.

@SableIndex | @SableIndexDiscussion
82
[CRIME] Violent Crypto Robberies Top $30 Million in 2026

Violent criminals stole more than $30 million from crypto holders in the first half of 2026, Chainalysis reports.

In France, attackers are spreading beyond Paris: one family was forced to transfer about $820,000, while another couple was coerced into sending roughly $1 million in bitcoin.

Chainalysis points to leaked tax records and a separate breach affecting 50,000 users.

French authorities have made about 200 arrests as kidnappings and home invasions increasingly target relatives.

@SableIndex | @SableIndexDiscussion
👀62
[DEVELOPING · CRIME] CISA Warns TeamCity Flaw Is Being Exploited

CISA added CVE-2026-63077 to its exploited-vulnerability catalog following evidence of active exploitation against on-premise JetBrains TeamCity servers.

What to do: Patch TeamCity now and inspect exposed servers for signs of compromise.

The unauthenticated flaw bypasses authentication and enables remote code execution through the agent-polling protocol. A successful attack can expose build data, stored credentials and downstream software-delivery pipelines.

@SableIndex | @SableIndexDiscussion
5👀4
[CRIME] St. Louis Trio Charged Over $245M Bitcoin Kidnap Plot

Federal prosecutors charged three St. Louis men over an alleged plan to kidnap Veer Chetal.

Chetal pleaded guilty after prosecutors tied him to a $245 million Bitcoin theft; the group allegedly wanted his crypto.

Prosecutors say the trio stalked his Connecticut family in August 2024, carrying air rifles and walkie-talkies, then fled fearing cameras.

@SableIndex | @SableIndexDiscussion
84
[DEVELOPING · BREACH] Social Engineering Exposes Levi Strauss Corporate Data

Levi Strauss disclosed on Aug. 7 that social engineering gave an intruder access to three employees’ company-issued computers.

The company says corporate information was accessed and removed, but no consumer data was impacted.

Levi Strauss contained the breach and reported no business interruption; its investigation remains ongoing.

@SableIndex | @SableIndexDiscussion
🤩72
[DEVELOPING · CRIME] More Than 20 Arrested in Russian Crypto-Laundering Crackdown

Russian authorities arrested more than 20 people in a crackdown on a network accused of laundering cryptocurrency.

The case shows how “just receive and forward the coins” can turn an ordinary wallet into part of a criminal trail.

@SableIndex | @SableIndexDiscussion
🤩1355
🎉 $33x3 🎉

Requirements:
• Join @SableIndex
• Join @SableIndexOTC


Participants: 387

Giveaway Ended

🍑 Winners:
@outflows
@legendop
@highroler

Paid @sableindexvouch
Please open Telegram to view this post
VIEW IN TELEGRAM
844👀1194
[FRAUD] Trezor User Loses $7 Million in Seed-phrase Phishing Scam

A crypto user lost 113 BTC worth about $7 million after entering a seed phrase on a fake Trezor website.

The site reportedly appeared as a sponsored Google result, turning an ordinary search into the attacker's delivery channel.

@SableIndex | @SableIndexDiscussion
4👀2213💊10
[MALWARE] Fake CAPTCHA Tricks Mac Users Into Installing Wallet-Stealing Malware

Fake CAPTCHA pages trick Mac users into pasting a Terminal command that starts a password- and wallet-stealing infection.

- The fake CAPTCHA is not a test. It asks the victim to run the malware manually.

- The command downloads a script, profiles the Mac and fetches a version built for its processor.

- It steals browser passwords, can prompt for the Mac password, and can drain wallets.


@SableIndex | @SableIndexDiscussion
9👀5😴4